Description
SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect forged emails.
Published: 2026-03-04
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Inability to detect forged PGP-signed emails
Action: Patch Upgrade
AI Analysis

Impact

SEPPmail Secure Email Gateway versions before 15.0.1 fail to communicate the outcome of PGP signature verification, making it impossible to distinguish legitimate signed messages from forged ones. This flaw in the security checking process (CWE‑347) undermines email authenticity and integrity, allowing an attacker to send emails that appear to be signed by a trusted sender while actually containing malicious content. The primary consequence is that users may unknowingly trust false messages, enabling phishing, spoofing, and social‑engineering attacks.

Affected Systems

Affected are all deployments of SEPPmail Secure Email Gateway running any version older than 15.0.1, including the standard gateway software and its secure email component, as identified by the vendor’s product name and the associated CPEs. No later releases contain the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity while the EPSS score of less than 1% shows that exploitation is currently unlikely. The vulnerability is not listed in CISA KEV. Exploitation requires the delivery of a crafted email that the gateway processes; the attacker does not need elevated privileges. Based on the description, the likely attack vector is the transmission of a malicious email to a target user. The risk is limited to the integrity of email content, but because forged messages can be used for phishing, the potential impact on users and organizations can be significant.

Generated by OpenCVE AI on April 17, 2026 at 13:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SEPPmail Secure Email Gateway to version 15.0.1 or later, which fixes the signature result communication issue.
  • Configure the gateway to enforce PGP signature verification and make the result visible in logs so that forged messages are identified.
  • As a temporary countermeasure, set the gateway to block or quarantine any email that lacks a valid PGP signature until the patch is applied.

Generated by OpenCVE AI on April 17, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 05 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Seppmail seppmail
CPEs cpe:2.3:a:seppmail:seppmail:*:*:*:*:*:*:*:*
Vendors & Products Seppmail seppmail
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 04 Mar 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
Description SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect forged emails.
Title Missing PGP Signature Tag
First Time appeared Seppmail
Seppmail seppmail Secure Email Gateway
Weaknesses CWE-347
CPEs cpe:2.3:a:seppmail:seppmail_secure_email_gateway:*:*:*:*:*:*:*:*
Vendors & Products Seppmail
Seppmail seppmail Secure Email Gateway
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Seppmail Seppmail Seppmail Secure Email Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-03-04T21:26:24.749Z

Reserved: 2026-02-19T13:56:30.878Z

Link: CVE-2026-2746

cve-icon Vulnrichment

Updated: 2026-03-04T21:26:21.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-04T09:15:57.960

Modified: 2026-03-05T15:25:57.563

Link: CVE-2026-2746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T13:15:19Z

Weaknesses